Fortunately, the bug has been fixed by PayPal. How the Stored XSS Attack Works? source: www.techworm.net